peter bassill · operator
$ cve CVE-2007-1548 JSON

CVE-2007-1548 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 1.8% (pctl 78)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not properly filter certain characters in SQL commands, which allows remote attackers to execute arbitrary SQL commands via \"' (backslash double-quote quote) sequences, which are collapsed into \'', as demonstrated via the name parameter to forum/pop_up_member_search.asp.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS1.79% — more likely to be exploited than 78% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2007-03-20
Last modified2026-06-16

Affected (1)

VendorProduct
webwizguideweb wiz forums

Public exploits

SourceTitleDate
exploit-dbWeb Wiz Forums 8.05 - String Filtering SQL Injection2007-03-20

References

→ the Explorer  ·  watch your stack  ·  NVD